The invention discloses a method and
system for establishing a
secure channel. The method comprises a step of receiving a second cross
certificate sent by a second
virtual network function instance, a step of verifying whether the second signature of the second cross
certificate is correct according to pre-stored signature information, a step of obtaining a stored first cross
certificate when the
verification is correct, a step of inquiring the local certificate
revocation list of second certificate management mechanism
interconnection end through a first management channel according to an
interconnection agreement agreed in advance, a step of verifying whether the first cross certificate and the second cross certificate are valid or not according to the certificate
revocation list, a step of sending a second
virtual network function instance to the first certificate when the
verification is valid, a step of sending a communication
IP address to the second
virtual network function instance after a preset
verification time, a step of receiving the message returned by the second virtual network function instance, and a step of establishing a
secure channel based on the message. According to the method and the
system, the establishment of the
secure channel between VNF instances in different security domains is realized, and the problem of the difficult realization of certificate management in a virtual environment is solved.